Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-25295 | 1 Opencats | 1 Opencats | 2021-01-26 | 4.3 MEDIUM | 6.1 MEDIUM |
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues. | |||||
CVE-2010-3906 | 2 Git, Git-scm | 2 Git, Git | 2021-01-26 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters. | |||||
CVE-2017-1000488 | 2 Acquia, Mautic | 2 Mautic, Mautic | 2021-01-25 | 4.3 MEDIUM | 6.1 MEDIUM |
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form. | |||||
CVE-2018-11198 | 1 Acquia | 1 Mautic | 2021-01-25 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json. | |||||
CVE-2020-15864 | 1 Quali | 1 Cloudshell | 2021-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page. | |||||
CVE-2020-13134 | 1 Tufin | 1 Securechange | 2021-01-22 | 3.5 LOW | 4.8 MEDIUM |
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1. | |||||
CVE-2020-13133 | 1 Tufin | 1 Securechange | 2021-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) unauthenticated users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1 | |||||
CVE-2020-28707 | 1 Stockdio | 1 Stockdio Historical Chart | 2021-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() event is not validated. The stockdio_eventer function listens for any postMessage event. After a message event is sent to the application, this function sets the "e" variable as the event and checks that the types of the data and data.method are not undefined (empty) before proceeding to eval the data.method received from the postMessage. However, on a different website. JavaScript code can call window.open for the vulnerable WordPress instance and do a postMessage(msg,'*') for that object. | |||||
CVE-2020-19362 | 1 Vtiger | 1 Vtiger Crm | 2021-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. | |||||
CVE-2021-20619 | 1 Weseek | 1 Growi | 2021-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors. | |||||
CVE-2020-19361 | 1 Medintux | 1 Medintux | 2021-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. | |||||
CVE-2021-3137 | 1 Xwiki | 1 Xwiki | 2021-01-22 | 3.5 LOW | 5.4 MEDIUM |
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section. | |||||
CVE-2021-23838 | 1 Flatcore | 1 Flatcore | 2021-01-22 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter HTTP request body parameter for the acp interface. The affected parameter accepts malicious client-side script without proper input sanitization. For example, a malicious user can leverage this vulnerability to steal cookies from a victim user and perform a session-hijacking attack, which may then lead to unauthorized access to the site. | |||||
CVE-2021-23836 | 1 Flatcore | 1 Flatcore | 2021-01-22 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected parameter without any form of input sanitization. The injected payload will be executed in the browser of a user whenever one visits the affected module page. | |||||
CVE-2020-25385 | 1 Nagios | 1 Log Server | 2021-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page. | |||||
CVE-2020-27851 | 1 Rocketgenius | 1 Gravityforms | 2021-01-21 | 3.5 LOW | 5.4 MEDIUM |
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.). | |||||
CVE-2020-27852 | 1 Rocketgenius | 1 Gravityforms | 2021-01-21 | 3.5 LOW | 5.4 MEDIUM |
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.). | |||||
CVE-2020-27850 | 1 Rocketgenius | 1 Gravityforms | 2021-01-21 | 3.5 LOW | 4.8 MEDIUM |
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.). | |||||
CVE-2021-25324 | 1 Misp | 1 Misp | 2021-01-21 | 4.3 MEDIUM | 6.1 MEDIUM |
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp. | |||||
CVE-2021-3184 | 1 Misp | 1 Misp | 2021-01-21 | 4.3 MEDIUM | 6.1 MEDIUM |
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button. |